Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.0%—Pypa PIPOpensuse LeapDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+14/9/202017/6/2026
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
ModificadaAlta (7.8)1.8%💥 PoCPypa PIP8/5/202017/6/2026
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the…
ModificadaMedia (5.9)8.0%💥 ExploitPypa PIPVirtualenvFedoraproject FedoraRedhat Openshift+25/11/201916/6/2026
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
ModificadaBaja (2.1)0.39%—Pypa PIPOracle Solaris24/11/201417/6/2026
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
ModificadaBaja (2.1)0.36%—Pypa PIPFedoraproject Fedora17/8/201316/6/2026
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
ModificadaMedia (6.8)6.2%—Pypa PIP6/8/201316/6/2026
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.
ModificadaAlta (7.5)14%💥 ExploitPypam16/6/201216/6/2026
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.